AplusWebMaster
Topic Starter
FYI…
- http://www.securityfocus.com/archive/1/455965
Michal Zalewski - Jan 04 2007 10:22PM
"A while ago, apparently angry with Larry Seltzer, I penned a quick write-up on the possible issues with race conditions…Today, inspired by Brian Krebs' report* on MSIE's stellar track of security response that we all owe to responsible disclosure, I thought it would be a brilliant idea to test MSIE for the same class of problems (they had half a year to take notice of my original rant)…."
(…resulting in "Concurrency strikes MSIE (potentially exploitable msxml3 flaws)")
- http://www.securityfocus.com/archive/1/455967/30/0/threaded
Larry Seltzer - Jan 04 2007 10:36PM
"I hope you're still not angry!…"
Internet Explorer Unsafe for 284 Days in 2006
* http://blog.washingtonpost.com/securityfix…safe_for_2.html
January 4, 2007; 6:45 AM ET
- http://nvd.nist.gov/nvd.cfm?cvename=CVE-2007-0099
Last revised: 1/8/2007
Impact
CVSS Severity: 2.7 (Low)
Range: Remotely exploitable
Authentication: Not required to exploit
Impact Type: Allows disruption of service
Vulnerable software and versions: MSIE 6, MSIE 7…
Vulnerability Type: Race Condition…
- http://isc.sans.org/diary.html?storyid=2004
Last Updated: 2007-01-09 02:29:36 UTC

- http://www.securityfocus.com/archive/1/455965
Michal Zalewski - Jan 04 2007 10:22PM
"A while ago, apparently angry with Larry Seltzer, I penned a quick write-up on the possible issues with race conditions…Today, inspired by Brian Krebs' report* on MSIE's stellar track of security response that we all owe to responsible disclosure, I thought it would be a brilliant idea to test MSIE for the same class of problems (they had half a year to take notice of my original rant)…."
(…resulting in "Concurrency strikes MSIE (potentially exploitable msxml3 flaws)")
- http://www.securityfocus.com/archive/1/455967/30/0/threaded
Larry Seltzer - Jan 04 2007 10:36PM
"I hope you're still not angry!…"
Internet Explorer Unsafe for 284 Days in 2006
* http://blog.washingtonpost.com/securityfix…safe_for_2.html
January 4, 2007; 6:45 AM ET
- http://nvd.nist.gov/nvd.cfm?cvename=CVE-2007-0099
Last revised: 1/8/2007
Impact
CVSS Severity: 2.7 (Low)
Range: Remotely exploitable
Authentication: Not required to exploit
Impact Type: Allows disruption of service
Vulnerable software and versions: MSIE 6, MSIE 7…
Vulnerability Type: Race Condition…
- http://isc.sans.org/diary.html?storyid=2004
Last Updated: 2007-01-09 02:29:36 UTC